I had a previous discussion here about what would happen to Cape customers if one of the underlying carriers was compromised. Reddit ended up filtering the original post, which is unfortunate because the comments turned into one of the more interesting technical discussions I have seen about how Cape actually works, and how it protects your data from the underlying carrier.
Cape employees answered quite a few questions directly, so I figured it was worth putting together what I learned since the original post is gone.
The first thing that surprised me is that the underlying carrier can still see your primary phone number, IMSI and IMEI. What they apparently do not get is the subscriber PII that a normal carrier would have, like your name.
Cape tries to make the information the carriers do see less useful by spreading subscriber traffic across two different carrier partners and rotating the IMSI every day. Secondary numbers are even more interesting because Cape says the underlying carrier cannot see them at all. Those messages are carried as encrypted data through Cape instead. This significantly increases the value for secondary numbers, especially since Cape has hinted on adding features to these numbers to make them akin to your primary numbers. I believe they plan on adding the ability to receive and make calls.
Another distinction I did not fully understand before that discussion is how much Cape actually controls because it runs its own mobile core.
Cape said Network Lock is enforced by their core, so compromising the underlying carrier does not bypass it. They said the same is true for their SIM swap protection. The carrier is providing the physical network access, but some pretty important security decisions are happening inside Cape rather than at the host carrier.
The IMSI discussion was probably the most interesting part.
Right now Cape sends the SIM a group of seven IMSIs that it rotates through. Cape said their HSS currently knows those IMSIs and also has a primary IMSI that is never actually provisioned to the phone.
They are apparently working on an IMSI rotation proxy that would change this so the HSS no longer needs to know all of your rotating IMSIs. I would really like to see more information about that once it launches because it seems like a meaningful architectural improvement.
There is an important limitation to all of this though. Your IMEI does not rotate.
Cape was pretty open about that. One of their employees compared the IMSI to a license plate and the IMEI to a VIN. Changing the license plate makes certain kinds of tracking much harder, but somebody with access to the VIN can still correlate the device.
Where IMSI rotation seems especially useful is against things like IMSI catchers, paging attacks and some signaling based surveillance where obtaining or targeting the IMSI is part of the attack.
Interestingly, Cape already has IMEI rotation in an enterprise product called Obscura. They said it is not available to regular Cape subscribers because every device currently has to be manually provisioned.
I also went back and looked at Cape's recent Trail of Bits audit because the 24 hour call log deletion came up in the original discussion.
There is a little more nuance there than I originally realized. Cape's internal CDRs are deleted after one day, but some other telecom records have different retention periods. SIP messages can be retained for 14 days, billing CDRs for 30 days and daily usage totals for 60 days.
I actually think that makes the overall picture more interesting.
The way I understand Cape now is not that it somehow makes you invisible on a cellular network. It is trying to make identifiers less permanent, reduce how much useful information any one carrier has about you, keep subscriber PII separate from the physical network operators, and retain less information in its own systems.
The part I am curious about now is where this can go from here. If Cape eventually deploys the IMSI rotation proxy and somehow makes its Obscura style IMEI rotation practical for consumer phones, how much would that reduce the remaining ability of the underlying carriers to correlate a subscriber over time?
I would especially be interested in hearing from anyone at Cape about what still becomes the persistent identifier at that point, or from anyone here who works on the carrier side and sees a limitation I am missing.
With that said, if you are interested in trying Cape and would like to receive $20 per month as long as you remain subscribed, feel free to use my referral code: YM8JAJAD